{"schema_version":1,"title":"gogs.io/gogs (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in gogs.io/gogs (Go): 0 in the last 7 days and 0 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-52816, was published on 24 June 2026.","url":"https://junglewise.ai/threats/technologies/gogs-io-gogs","json_url":"https://junglewise.ai/threats/technologies/gogs-io-gogs.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gogs-io-gogs","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":25,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":24},"latest":[{"cve":"CVE-2026-52816","cvss":5.4,"slug":"cve-2026-52816-gogs-stored-xss-in-jupyter-notebook-sanitizer-endpoint","title":"Gogs stored XSS in Jupyter Notebook sanitizer endpoint","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.753+00:00","url":"https://junglewise.ai/threats/cve-2026-52816-gogs-stored-xss-in-jupyter-notebook-sanitizer-endpoint"},{"cve":"CVE-2026-52815","cvss":5.5,"slug":"cve-2026-52815-gogs-unauthenticated-information-disclosure-in-organization-teams","title":"Gogs unauthenticated information disclosure in organization teams API","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.627+00:00","url":"https://junglewise.ai/threats/cve-2026-52815-gogs-unauthenticated-information-disclosure-in-organization-teams"},{"cve":"CVE-2026-52814","cvss":5.5,"slug":"cve-2026-52814-gogs-denial-of-service-via-ssh-handshake-stall-in-built-in-ssh","title":"Gogs Denial of Service via SSH handshake stall in built-in SSH server","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.497+00:00","url":"https://junglewise.ai/threats/cve-2026-52814-gogs-denial-of-service-via-ssh-handshake-stall-in-built-in-ssh"},{"cve":"CVE-2026-52813","cvss":10,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52812","cvss":7.1,"slug":"cve-2026-52812-gogs-git-lfs-cross-repository-disclosure-via-insufficient-oid","title":"Gogs Git LFS cross-repository disclosure via insufficient OID verification","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:57.223+00:00","url":"https://junglewise.ai/threats/cve-2026-52812-gogs-git-lfs-cross-repository-disclosure-via-insufficient-oid"},{"cve":"CVE-2026-52811","cvss":9.9,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52810","cvss":8.1,"slug":"cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization","title":"Gogs improper access control in Git smart HTTP push authorization","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.96+00:00","url":"https://junglewise.ai/threats/cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization"},{"cve":"CVE-2026-52809","cvss":6.8,"slug":"cve-2026-52809-gogs-insufficient-session-expiration-in-password-reset-tokens","title":"Gogs insufficient session expiration in password reset tokens","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.827+00:00","url":"https://junglewise.ai/threats/cve-2026-52809-gogs-insufficient-session-expiration-in-password-reset-tokens"},{"cve":"CVE-2026-52808","cvss":7.1,"slug":"cve-2026-52808-gogs-incorrect-authorization-in-repository-settings-api","title":"Gogs incorrect authorization in repository settings API","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.693+00:00","url":"https://junglewise.ai/threats/cve-2026-52808-gogs-incorrect-authorization-in-repository-settings-api"},{"cve":"CVE-2026-52807","cvss":0,"slug":"cve-2026-52807-gogs-stored-dom-based-xss-in-milestone-dropdown-on-new-issue-page","title":"Gogs stored DOM-based XSS in milestone dropdown on New Issue page","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.57+00:00","url":"https://junglewise.ai/threats/cve-2026-52807-gogs-stored-dom-based-xss-in-milestone-dropdown-on-new-issue-page"},{"cve":"CVE-2026-52806","cvss":9.9,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"},{"cve":"CVE-2026-52805","cvss":8.7,"slug":"cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync","title":"Gogs SSRF in repository migration and mirror sync","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.317+00:00","url":"https://junglewise.ai/threats/cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync"},{"cve":"CVE-2026-52804","cvss":5.5,"slug":"cve-2026-52804-gogs-privilege-escalation-in-changecollaborationaccessmode","title":"Gogs privilege escalation in ChangeCollaborationAccessMode","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.187+00:00","url":"https://junglewise.ai/threats/cve-2026-52804-gogs-privilege-escalation-in-changecollaborationaccessmode"},{"cve":"CVE-2026-52802","cvss":5.4,"slug":"cve-2026-52802-gogs-open-redirect-in-issamesite-validation","title":"Gogs open redirect in IsSameSite validation","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.057+00:00","url":"https://junglewise.ai/threats/cve-2026-52802-gogs-open-redirect-in-issamesite-validation"},{"cve":"CVE-2026-52801","cvss":8.1,"slug":"cve-2026-52801-gogs-ssrf-and-local-file-disclosure-in-mirror-settings","title":"Gogs SSRF and local file disclosure in Mirror Settings","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.93+00:00","url":"https://junglewise.ai/threats/cve-2026-52801-gogs-ssrf-and-local-file-disclosure-in-mirror-settings"},{"cve":"CVE-2026-52800","cvss":8.8,"slug":"cve-2026-52800-gogs-csrf-in-organization-team-management","title":"Gogs CSRF in organization team management","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.8+00:00","url":"https://junglewise.ai/threats/cve-2026-52800-gogs-csrf-in-organization-team-management"},{"cve":"CVE-2026-52799","cvss":7.5,"slug":"cve-2026-52799-gogs-missing-authorization-in-attachment-download-endpoint","title":"Gogs missing authorization in attachment download endpoint","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.67+00:00","url":"https://junglewise.ai/threats/cve-2026-52799-gogs-missing-authorization-in-attachment-download-endpoint"},{"cve":"CVE-2026-52798","cvss":8.9,"slug":"cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview","title":"Gogs stored XSS in Jupyter notebook preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.533+00:00","url":"https://junglewise.ai/threats/cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview"},{"cve":"CVE-2026-52797","cvss":8.5,"slug":"cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview","title":"Gogs path traversal and argument injection in git diff preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.403+00:00","url":"https://junglewise.ai/threats/cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview"},{"cve":"CVE-2026-52796","cvss":3.5,"slug":"cve-2026-52796-gogs-denial-of-service-via-malformed-issue-index-pattern","title":"Gogs denial of service via malformed issue index pattern","severity":"low","exploited":false,"published_at":"2026-06-24T21:16:55.27+00:00","url":"https://junglewise.ai/threats/cve-2026-52796-gogs-denial-of-service-via-malformed-issue-index-pattern"},{"cve":"CVE-2026-47267","cvss":8.3,"slug":"cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass","title":"Gogs SSRF via webhook redirect bypass","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:54.347+00:00","url":"https://junglewise.ai/threats/cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass"},{"cve":"CVE-2026-25119","cvss":7.7,"slug":"cve-2026-25119-gogs-authentication-bypass-via-spoofed-reverse-proxy-headers","title":"Gogs authentication bypass via spoofed reverse proxy headers","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:52.903+00:00","url":"https://junglewise.ai/threats/cve-2026-25119-gogs-authentication-bypass-via-spoofed-reverse-proxy-headers"},{"cve":"CVE-2025-64719","cvss":4.9,"slug":"cve-2025-64719-gogs-denial-of-service-via-malformed-filenames-in-repository-or","title":"Gogs denial of service via malformed filenames in repository or wiki","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.007+00:00","url":"https://junglewise.ai/threats/cve-2025-64719-gogs-denial-of-service-via-malformed-filenames-in-repository-or"},{"cvss":8.5,"slug":"gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b","title":"Gogs XSS in Jupyter notebook renderer via outdated notebookjs","severity":"high","exploited":false,"published_at":"2026-06-19T21:42:52+00:00","url":"https://junglewise.ai/threats/gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b"},{"cve":"CVE-2018-20303","cvss":7.5,"slug":"cve-2018-20303-gogs-directory-traversal-in-file-upload-functionality","title":"Gogs directory traversal in file-upload functionality","severity":"high","exploited":false,"published_at":"2022-05-14T01:37:52+00:00","url":"https://junglewise.ai/threats/cve-2018-20303-gogs-directory-traversal-in-file-upload-functionality"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"},{"name":"github.com/juev/nebula-mesh (Go)","slug":"github-com-juev-nebula-mesh","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/github-com-juev-nebula-mesh"}],"technology":{"hub":true,"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://gogs.io/","repo_url":"https://github.com/gogs/gogs","description":"Gogs is a self-hosted Git service written in the Go programming language.","url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},"most_severe":[{"cve":"CVE-2026-52813","cvss":10,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52811","cvss":9.9,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52806","cvss":9.9,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"},{"cve":"CVE-2026-52798","cvss":8.9,"slug":"cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview","title":"Gogs stored XSS in Jupyter notebook preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.533+00:00","url":"https://junglewise.ai/threats/cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview"},{"cve":"CVE-2026-52800","cvss":8.8,"slug":"cve-2026-52800-gogs-csrf-in-organization-team-management","title":"Gogs CSRF in organization team management","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.8+00:00","url":"https://junglewise.ai/threats/cve-2026-52800-gogs-csrf-in-organization-team-management"},{"cve":"CVE-2026-52805","cvss":8.7,"slug":"cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync","title":"Gogs SSRF in repository migration and mirror sync","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.317+00:00","url":"https://junglewise.ai/threats/cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync"},{"cve":"CVE-2026-52797","cvss":8.5,"slug":"cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview","title":"Gogs path traversal and argument injection in git diff preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.403+00:00","url":"https://junglewise.ai/threats/cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview"},{"cvss":8.5,"slug":"gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b","title":"Gogs XSS in Jupyter notebook renderer via outdated notebookjs","severity":"high","exploited":false,"published_at":"2026-06-19T21:42:52+00:00","url":"https://junglewise.ai/threats/gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b"},{"cve":"CVE-2026-47267","cvss":8.3,"slug":"cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass","title":"Gogs SSRF via webhook redirect bypass","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:54.347+00:00","url":"https://junglewise.ai/threats/cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass"},{"cve":"CVE-2026-52810","cvss":8.1,"slug":"cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization","title":"Gogs improper access control in Git smart HTTP push authorization","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.96+00:00","url":"https://junglewise.ai/threats/cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}